Jobs · Legal · Pennsylvania

Lead Risk and Compliance Analyst

Highmark Health · Pittsburgh, PA · 1 wk ago
LegalFull-time

This role supports all risk and compliance assessment activities across a broad range of frameworks including NIST, HITRUST, PCI, HIPAA, SOC, MAR, CMS, and JCAHO. The incumbent partners with organizational risk and business partners, the technology organization, and global delivery teams to meet Highmark Health’s mission requirements in alignment with the enterprise risk appetite. A proactive mindset and comfort working in a highly matrixed environment are essential.

Responsibilities

  • Provide input and consultation on risk and assurance reporting, along with terms and conditions in supplier contracts.
  • Collaborate and consult with other areas (e.g., Procurement, Privacy, Information Security, Legal) throughout the compliance/contract lifecycle, including internal business and contract administration partners.
  • Interpret inherent risk assessment results and develop third-party and overall assurance plans to address relevant risk areas and ensure proper controls are implemented.
  • Review and interpret information provided by third parties; perform qualitative and quantitative impact assessments; conduct additional information gathering and risk assessments with suppliers as needed; document and report results.
  • Review draft reports and other management reporting deliverables prior to submission to the Enterprise Director and Vice President.
  • Oversee and review work prepared by less experienced team members to ensure audit quality standards are consistently met.
  • Oversee the delivery and timely completion of risk questionnaires and other risk assessments; lead impact assessment activities.
  • Lead the team to ensure compliance requirements are met across the Enterprise.
  • Train and mentor team members on multi-faceted relationships, platform customer dependencies, and interpretation of complex contract agreements.
  • Interpret complex data flow, information sharing activities, and information safeguards into simplified, high-level terminology and/or process/data flows.
  • Maintain Enterprise reporting dashboards in RSA Archer applications to keep information complete, accurate, and current.
  • Prepare and assist with the delivery of reports to management.
  • Maintain and review updates to profiles, engagements, assessments, contracts, and other third-party information in RSA Archer, including periodic or automated refresh of supplier data from ancillary systems.
  • Interface with business areas, technical staff, project teams, and third parties to lead and execute cross-functional risk assurance projects.
  • Provide consultation and direction throughout; evaluate risks relative to new or existing programs and initiatives that support the Enterprise's strategic direction and core operations.
  • Ensure departmental desk-level procedures, risk assessment methodology, assessment procedures, questionnaires, and training are updated periodically; monitor compliance with departmental metrics, internal control activities, contractual obligations, and regulatory requirements; respond to customer inquiries/audits.
  • Build and maintain strong working relationships with all Enterprise companies to support the management of risks across multiple departments.
  • Perform other duties as assigned or requested.

Requirements

  • Bachelor’s Degree in Accounting, Finance, Business Administration/Management, Information Technology, Pre-Law, or a related field or 6 years of related and progressive experience in lieu of a degree.
  • 7 years of experience in Audit and Compliance, including:
    • 5 years in Business Process Design
    • 3 years in Project Management

Preferred Qualifications

  • Master’s Degree in Accounting, Finance, Business Administration/Management, Information Technology, Pre-Law, or a related field.
  • Certifications (any of the following):
    • Certified Public Accountant (CPA)
    • Certified Information Systems Auditor (CISA)
    • Certified Information Privacy Professional (CIPP)
    • Certified Information Systems Security Professional (CISSP)

Skills

  • Expert knowledge of business and technology processes, risk and control frameworks, and assessment methodologies, particularly as applied to healthcare (payer and provider) business processes.
  • Knowledge of relevant regulatory guidelines, vendor management, sourcing and procurement, and completing assessments of vendors.
  • Excellent resource and project planning capabilities, decision-making skills, and a history of results-oriented delivery.
  • Effective team building across a cross-campus and diverse team of management and staff.
  • Strong written and verbal communication skills for diverse audiences (senior management, board, peers, and team).
  • Strong relationship-building skills and ability to influence with and without authority in a matrixed organization.
  • Developed leadership qualities with an ability to motivate and inspire a group of individuals to achieve superior results.
  • High capacity to think analytically, interpret information/observations, apply judgment, and make effective, strategic decisions.

Schedule

  • Office-based position.
  • Travel requirement: 0% - 25%.
  • Occasional teaching/training of others.
  • Rarely lifts 10 to 25 pounds; rarely lifts 25 to 50 pounds.

Similar jobs

Sales Lead

1915 South | AshleyHarahan, LA· 1 mo ago
OTHRapply on apply.workable.com

Sales Lead

1915 South | AshleyPonchatoula, LA· 1 mo ago
OTHRapply on apply.workable.com

Sales Lead

Foot LockerLanghorne, PA· 1 mo ago
Business Development$20.5/hrapply on careers.footlocker.com

Sales Lead

JourneysMonroeville, PA· 6 mo ago
Business Developmentapply on cta.cadienttalent.com

Sales Lead

Claire'sAlgonquin, IL· 3 wk ago
Business Developmentapply on secure5.saashr.com

Sales Lead

Cole HaanWoodstock, GA· 2 mo ago
Business Development$17–$18.5/hrapply on myjobs.adp.com